Количество 26 124
Количество 26 124
CVE-2025-68188
tcp: use dst_dev_rcu() in tcp_fastopen_active_disable_ofo_check()
CVE-2025-6817
HDF5 H5Centry.c H5C__load_entry resource consumption
CVE-2025-68175
media: nxp: imx8-isi: Fix streaming cleanup on release
CVE-2025-68174
amd/amdkfd: enhance kfd process check in switch partition
CVE-2025-6816
HDF5 H5Ofsinfo.c H5O__fsinfo_encode heap-based overflow
CVE-2025-68161
Apache Log4j Core: Missing TLS hostname verification in Socket appender
CVE-2025-68156
Expr has Denial of Service via Unbounded Recursion in Builtin Functions
CVE-2025-68151
CoreDNS gRPC/HTTPS/HTTP3 servers lack resource limits, enabling DoS via unbounded connections and oversized messages
CVE-2025-68146
filelock has TOCTOU race condition that allows symlink attacks during lock file creation
CVE-2025-68121
Unexpected session resumption in crypto/tls
CVE-2025-68114
Capstone doesn't check vsnprintf return in SStream_concat, allows stack buffer underflow and overflow
CVE-2025-67897
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet.
CVE-2025-67873
Capstone doesn't check Skipdata length, leading to cs_insn.bytes heap buffer overflow
CVE-2025-67733
Valkey Affected by RESP Protocol Injection via Lua error_reply
CVE-2025-6750
HDF5 H5Omtime.c H5O__mtime_new_encode heap-based overflow
CVE-2025-67030
Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code
CVE-2025-66476
Vim for Windows Uncontrolled Search Path Element Remote Code Execution Vulnerability
CVE-2025-66471
urllib3 Streaming API improperly handles highly compressed data
CVE-2025-66442
In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected.
CVE-2025-66418
urllib3 allows an unbounded number of links in the decompression chain
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-68188 tcp: use dst_dev_rcu() in tcp_fastopen_active_disable_ofo_check() | 0% Низкий | 5 месяцев назад | ||
CVE-2025-6817 HDF5 H5Centry.c H5C__load_entry resource consumption | 0% Низкий | 12 месяцев назад | ||
CVE-2025-68175 media: nxp: imx8-isi: Fix streaming cleanup on release | 0% Низкий | 7 месяцев назад | ||
CVE-2025-68174 amd/amdkfd: enhance kfd process check in switch partition | 0% Низкий | 7 месяцев назад | ||
CVE-2025-6816 HDF5 H5Ofsinfo.c H5O__fsinfo_encode heap-based overflow | CVSS3: 3.3 | 0% Низкий | 12 месяцев назад | |
CVE-2025-68161 Apache Log4j Core: Missing TLS hostname verification in Socket appender | 1% Низкий | 8 месяцев назад | ||
CVE-2025-68156 Expr has Denial of Service via Unbounded Recursion in Builtin Functions | CVSS3: 7.5 | 0% Низкий | 8 месяцев назад | |
CVE-2025-68151 CoreDNS gRPC/HTTPS/HTTP3 servers lack resource limits, enabling DoS via unbounded connections and oversized messages | CVSS3: 7.5 | 0% Низкий | 7 месяцев назад | |
CVE-2025-68146 filelock has TOCTOU race condition that allows symlink attacks during lock file creation | CVSS3: 6.3 | 0% Низкий | 7 месяцев назад | |
CVE-2025-68121 Unexpected session resumption in crypto/tls | 1% Низкий | 5 месяцев назад | ||
CVE-2025-68114 Capstone doesn't check vsnprintf return in SStream_concat, allows stack buffer underflow and overflow | CVSS3: 4.8 | 0% Низкий | 8 месяцев назад | |
CVE-2025-67897 In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. | 0% Низкий | 8 месяцев назад | ||
CVE-2025-67873 Capstone doesn't check Skipdata length, leading to cs_insn.bytes heap buffer overflow | CVSS3: 4.8 | 0% Низкий | 5 месяцев назад | |
CVE-2025-67733 Valkey Affected by RESP Protocol Injection via Lua error_reply | CVSS3: 8.5 | 1% Низкий | 6 месяцев назад | |
CVE-2025-6750 HDF5 H5Omtime.c H5O__mtime_new_encode heap-based overflow | CVSS3: 3.3 | 0% Низкий | 8 месяцев назад | |
CVE-2025-67030 Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code | CVSS3: 8.8 | 1% Низкий | 5 месяцев назад | |
CVE-2025-66476 Vim for Windows Uncontrolled Search Path Element Remote Code Execution Vulnerability | 0% Низкий | 8 месяцев назад | ||
CVE-2025-66471 urllib3 Streaming API improperly handles highly compressed data | 1% Низкий | 8 месяцев назад | ||
CVE-2025-66442 In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected. | 0% Низкий | 3 месяца назад | ||
CVE-2025-66418 urllib3 allows an unbounded number of links in the decompression chain | 1% Низкий | 8 месяцев назад |
Уязвимостей на страницу